From owner-freebsd-security Thu Jan 28 03:00:35 1999 Return-Path: Received: (from majordom@localhost) by hub.freebsd.org (8.8.8/8.8.8) id DAA26482 for freebsd-security-outgoing; Thu, 28 Jan 1999 03:00:35 -0800 (PST) (envelope-from owner-freebsd-security@FreeBSD.ORG) Received: from ns1.yes.no (ns1.yes.no [195.204.136.10]) by hub.freebsd.org (8.8.8/8.8.8) with ESMTP id DAA26468 for ; Thu, 28 Jan 1999 03:00:31 -0800 (PST) (envelope-from eivind@bitbox.follo.net) Received: from bitbox.follo.net (bitbox.follo.net [195.204.143.218]) by ns1.yes.no (8.9.1a/8.9.1) with ESMTP id MAA20587; Thu, 28 Jan 1999 12:00:27 +0100 (CET) Received: (from eivind@localhost) by bitbox.follo.net (8.8.8/8.8.6) id MAA25489; Thu, 28 Jan 1999 12:00:27 +0100 (MET) Date: Thu, 28 Jan 1999 12:00:26 +0100 From: Eivind Eklund To: laurens van alphen Cc: freebsd-security@FreeBSD.ORG Subject: Re: Security breach or VM flaw? (security check output) Message-ID: <19990128120026.C24242@bitbox.follo.net> References: <000601be4a4b$360dcfb0$ac1010ac@cow.craxx.com> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii X-Mailer: Mutt 0.95.1i In-Reply-To: <000601be4a4b$360dcfb0$ac1010ac@cow.craxx.com>; from laurens van alphen on Thu, Jan 28, 1999 at 12:17:30AM +0100 Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk X-Loop: FreeBSD.org On Thu, Jan 28, 1999 at 12:17:30AM +0100, laurens van alphen wrote: > Hiya folks, > > This mornin' i received this daily security check output: > (of course, hostnames have been changes, dates/sizes have not) > > setuid diffs: > 40c40 > < -r-xr-s--- 1 bin kmem 49152 Jul 22 10:14:47 1998 /usr/bin/netstat > --- > > -r-xr-s--- 1 bin kmem 49152 Jan 28 02:30:23 1999 /usr/bin/netstat > > Is seems as if netstat has adopted the time at which it was executed. That's exactly what has happened. It was a bug in the VM system, where read only pages sometimes (very seldom) were marked as dirty. I think it has been fixed in 2.2.8+. Eivind. To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message